After attempting to get the program to work and failing, you’ll quickly become bored and uninstall it. However, the whole time the app is on board, it is doing quite a bit in the background.

None the wiser, you may have removed the app, but the damage has already been done.

To see what “Mayis Guzel Aydir” is really up to, we first look in the decompiled Jar code. Within the code, an OnCreate() function is found containing a suspicious website. The app directs to the suspicious website whenever the app is opened.

After manually browsing to the website found within the OnCreate() function, JavaScript code lies in wait. Once run, the JavaScript code randomly selects from a list of websites, and “clicks” (browses/opens) to them in the background. All the websites found in the list contain adult/explicit material.

Over and over again, the app clicks on these various websites. The purpose of this is to gain revenue on a pay-per-click basis; thus, it’s called a clicker. In this case, we call it Trojan.PornClicker. Every time the app clicks any of these websites, the bad guys get paid and you are left with some embarrassing network traffic.

“Mayis Guzel Aydir” had 1,000 – 5,000 installs and 3.2 star rating with 383 ratings given on Google Play at the time of this blog post. It had no description, and only a few screenshots of a calculator app which doesn’t exactly line up with the app name. There were also several other versions of this app with the same app name but a number at the end; i.e. “Mayis Guzel Aydir 2”. At time of writing, the app has been taken down, but there may be others still out there. Porn clickers are a lucrative money spinner.

Although you may expect something from Google Play to be safe, the lesson here is to always be wary of suspicious apps no matter the source. Even with all the checks Google performs on apps before allowing them on the Play store, no system can be one hundred percent safe when the bad guys are constantly looking for cracks to exploit.

December 18, 2018 - Why would a criminal want to hack your phone? Perhaps the better question may be: Why wouldn't they? We take a look at all the reasons hackers have for breaking into your most precious device—and what you can do to stop it.

December 17, 2018 - The next major Android version will be Android Q and not Android 9.1 Pie. In parallel, Google is also developing a new operating system based on its own microkernel called Fuchsia. Will this be the OS that replaces Android? Read on to find out.